Security vulnerability in Evergreen 1.6: patch or upgrade advised
On Thursday, June 17th, we realized that the open-ils.pcrud service, which provides permission-protected access to Evergreen data in the 1.6 release series, was subject to a security vulnerability. The vulnerability allows a user to access objects outside of the permissions they have been granted by supplying fleshing arguments to the open-ils.pcrud search service. By Thursday … Continue Reading about Security vulnerability in Evergreen 1.6: patch or upgrade advised →
PINES the day after Memorial Day, 2007-2010
Some of you may know that Lamar Veatch and I are working on an article on the history of Evergreen so we are busy with that work—and will possibly be posting bits and pieces here. I suspect that we will also assemble web-friendly materials for an online history somewhere but that in time. Dr. Veatch … Continue Reading about PINES the day after Memorial Day, 2007-2010 →
The Evergreen Superconsortium: The next stage in the evolution of Evergreen consortia
The two of us have seen aspects of the evolution of the Evergreen software ecosystem that was at once surprising and then obvious once it started to arise: the evolving superconsortium in the Evergreen community. This notion first occurred to us independently in early 2009 and, curiously, we each invented the same word to describe … Continue Reading about The Evergreen Superconsortium: The next stage in the evolution of Evergreen consortia →